{
  "id": "CON-023",
  "slug": "con-023",
  "title": "Evidence URLs must resolve without a login",
  "statement": "A submitted evidence URL must resolve, be publicly reachable, and not require authentication.",
  "rationale": "The most common evidence failure in practice is a cloud-storage link that shows a \"request access\" wall to anyone outside the organisation. The submitter tested it while logged in and saw their own file, so the failure is invisible from their side.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent artifact URL",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "TCR",
    "Twilio",
    "Bandwidth",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Set the link to \"anyone with the link can view\", or host the file somewhere public, then open it in a private browsing window to confirm.",
  "pitfalls": [
    "Google Drive and Dropbox default to organisation-only access, which looks fine to you and shows a wall to everyone else.",
    "A viewer page is not the file — link the direct image or PDF."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-023/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-023.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
